Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2021-21432 Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0… Vela 0.7.5+ Fix from $1,6002021-04-09 MEDIUM 6.5 CVE-2021-22865 An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web auth… Enterprise Server 2.21.18 / 2.22.10+ Fix from $1,6002021-04-02 HIGH 7.8 CVE-2021-25352 Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and mod… Bixby Voice 3.0.52.14+ Fix from $1,9502021-03-25 HIGH 7.1 CVE-2021-25353 Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Theme… Galaxy Themes 5.2.00.1215+ Fix from $1,9502021-03-25 MEDIUM 5.3 CVE-2021-25354 Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious… Internet 13.2.1.46+ Fix from $1,6002021-03-25 HIGH 7.8 CVE-2021-25355 Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking th… Notes 4.2.00.22+ Fix from $1,9502021-03-25 MEDIUM 6.5 CVE-2021-21362 MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before versio… Minio 2021-03-04t00-53-13z+ Fix from $1,6002021-03-08 HIGH 7.5 CVE-2020-27779 A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove … Enterprise Linux 2.06+ Fix from $1,9502021-03-03 MEDIUM 6.5 CVE-2021-22861 An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write ac… GitHub 2.20.24 / 2.21.15+ Fix from $1,6002021-03-03 MEDIUM 6.5 CVE-2021-22862 An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a rep… GitHub Mitigation only Fix from $1,6002021-03-03 HIGH 8.1 CVE-2021-22863 An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance … GitHub 2.20.24 / 2.21.15+ Fix from $1,9502021-03-03 HIGH 8.1 CVE-2021-21511 Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could … Emc Avamar Server Mitigation only Fix from $1,9502021-02-15 MEDIUM 5.3 CVE-2021-21026 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the i… Magento 2.3.6+ Fix from $1,6002021-02-11 HIGH 8.8 CVE-2020-24674 In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c… Symphony \+ Historian Mitigation only Fix from $1,9502020-12-22 MEDIUM 6.5 CVE-2020-26246 Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without hav… Pimcore 6.8.5+ Fix from $1,6002020-12-03 MEDIUM 5.3 CVE-2020-9049 A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta… C Cure Web after 5.6 Fix from $1,6002020-11-19 HIGH 8.2 CVE-2020-2050 An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to… Pan Os 8.1.17 / 9.0.11+ Fix from $1,9502020-11-12 MEDIUM 6.5 CVE-2020-26183 Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit t… Emc Networker 19.3.0.2+ Fix from $1,6002020-10-16 HIGH 8.1 CVE-2020-9048 A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated… Victor Web Client after 5.4.1 Fix from $1,9502020-10-08 HIGH 8.8 CVE-2020-7530 A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executabl… Scadapack 7x Remote Connect after 3.6.3.574 Fix from $1,9502020-09-16 HIGH 7.7 CVE-2020-16096 In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(… Command Centre 7.80.960 / 7.90.991+ Fix from $1,9502020-09-15 MEDIUM 6.5 CVE-2020-6311 Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per… Bank Analyzer Mitigation only Fix from $1,6002020-09-09 HIGH 7.8 CVE-2020-3394 A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could … Nx Os Mitigation only Fix from $1,9502020-08-27 HIGH 7.8 CVE-2020-7583 A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The applica… Automation License Manager 6.0.8+ Fix from $1,9502020-08-14 HIGH 8.8 CVE-2020-3386 A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privile… Data Center Network Manager 11.4+ Fix from $1,9502020-07-31 CRITICAL 9.9 CVE-2020-3374 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author… Sd Wan 18.4.5 / 19.2.2+ Fix from $2,3002020-07-31 HIGH 8.8 CVE-2020-14486 An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which … Openclinic Ga Mitigation only Fix from $1,9502020-07-29 MEDIUM 5.9 CVE-2020-3150 A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote… Rv110w Firmware 1.2.2.8 / 1.3.1.7+ Fix from $1,6002020-07-16 MEDIUM 6.5 CVE-2020-5356 Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulne… Powerprotect Data Manager 3.2 / 19.4+ Fix from $1,6002020-07-06 HIGH 8.8 CVE-2020-15087 In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. This impacts Presto server ins… Presto 337+ Fix from $1,9502020-06-30